<30 min Response

20+ Years Experience

Cyber Essentials Certified

Remote SOS Support

Cyber Essentials Cost in 2026: What You Will Pay and Whether You Need It

The Cyber Essentials cost is lower than most business owners expect. Certification starts at £320 plus VAT, and it comes with £25,000 of cyber liability insurance included. The harder question is not what it costs, but whether you actually need it, and what you will have to fix before you pass.

Here is the honest answer to both. For the full picture of what the scheme involves and how certification works, read our complete guide to Cyber Essentials.

Cyber Essentials cost: the 2026 prices

Cyber Essentials is a UK government backed scheme, run by IASME on behalf of the National Cyber Security Centre. The certification fee is set centrally and tiered by the size of your organisation.

Organisation sizeEmployeesCost (excluding VAT)
Micro0 to 9£320
Small10 to 49£440
Medium50 to 249£500
Large250 or more£600

That fee covers the assessment, the certificate and your listing on the public register. IASME reviews its pricing periodically, so check the current rate before you budget.

What about Cyber Essentials Plus?

Cyber Essentials Plus is the audited version. Rather than reviewing your answers, an assessor tests your systems directly with vulnerability scans and hands on checks of a sample of your devices.

It is priced individually rather than centrally, because the work depends on the size of your setup. Most SMEs pay between £1,500 and £3,000 plus VAT, on top of the basic certification, which you must hold first.

The cost nobody mentions

The certification fee is rarely the whole bill. The real cost is fixing whatever you fail on.

If your systems are already in good order, the fee is genuinely all you pay. If they are not, you may need to budget for:

  • Replacing unsupported software or hardware. This is the big one. Anything out of support is an automatic fail, with no exceptions
  • Turning on multi factor authentication across your accounts
  • Proper endpoint protection on every device
  • Patching brought up to date and kept there
  • Firewall and configuration changes

A business that has been well looked after tends to sail through. A business that has been neglected finds out, in detail, exactly how neglected it was. That is uncomfortable, but it is also the point of the exercise.

What you get for the money

Beyond the certificate itself, the scheme includes something most people miss.

£25,000 of cyber liability insurance, included at no extra cost, for UK organisations with turnover under £20 million that certify their whole business. That includes 24/7 incident response with technical, legal and crisis management support. For many small businesses, the insurance alone is worth more than the fee.

You also get the certificate, the NCSC badge for your website and tender documents, and a listing on the public register that clients and prospects can check.

Do you actually need Cyber Essentials?

Honestly, not every business does. Here is when it stops being optional.

You need it if you bid for public sector work. Most central government contracts require it, and it is mandatory for anything involving sensitive information.

You need it if you supply larger companies. Supply chain requirements are tightening fast. More and more large firms now ask their suppliers to prove certification, and they check the register. Defence supply chain contracts frequently require Cyber Essentials Plus specifically.

You should strongly consider it if you hold sensitive client data. Veterinary practices, solicitors, accountants, healthcare and financial services all sit here. A breach is not just embarrassing, it is a regulatory problem.

It is worth it for most SMEs regardless, because the five controls it enforces are the ones that stop the overwhelming majority of attacks. Most cyber attacks are not sophisticated. They are the digital equivalent of walking down a street trying every door handle.

You probably do not need Cyber Essentials Plus unless a client or contract specifically demands it. Do not pay for the audited version out of vanity.

The five controls you will be assessed on

Cyber Essentials tests five things. Nothing exotic, just the basics done properly.

  1. Firewalls. Controlling what can reach your network from outside
  2. Secure configuration. No default passwords, no unnecessary services running
  3. User access control. People have the access they need and nothing more, with admin rights tightly held
  4. Malware protection. Every device protected, properly
  5. Security update management. Everything patched, and nothing running past its support date

If you already have a good managed IT service, all five should already be in place. If they are not, that tells you something important about your current provider, and it is worth reading the signs it is time to change your IT support provider.

How long does it take?

If your systems are in order, certification can be completed in days. The self assessment is a questionnaire, signed off by a board member and marked by an assessor.

If they are not, the timeline depends entirely on the remediation work. Replacing an unsupported server is a project, not an afternoon.

Realistically, budget four to six weeks from starting to holding the certificate, and start earlier if you have a tender deadline. The certificate is valid for 12 months and must then be renewed.

How to pass first time

The single biggest cause of failure is submitting blind and discovering problems you could have found first.

  1. Do a gap analysis before you submit. Find out what you would fail on while it still costs nothing to fix
  2. Deal with unsupported software immediately. It is the most common automatic fail and the slowest to fix
  3. Turn on multi factor authentication everywhere. Cheap, fast, and it closes the door on the most common attack of all
  4. Scope it sensibly. Certify the whole organisation if you want the free insurance, but understand what is in scope before you answer
  5. Use the free readiness tool. IASME and the NCSC publish one at no cost. Work through it before you spend a penny

Frequently asked questions

How much does Cyber Essentials cost?

Cyber Essentials costs £320 plus VAT for organisations with 0 to 9 employees, £440 for 10 to 49 employees, £500 for 50 to 249, and £600 for 250 or more. The fee is set by IASME and includes the assessment, certificate and £25,000 of cyber liability insurance for eligible UK businesses.

How much does Cyber Essentials Plus cost?

Cyber Essentials Plus is quoted individually because it involves a hands on technical audit. Most UK SMEs pay between £1,500 and £3,000 plus VAT, in addition to the basic Cyber Essentials fee, which must be held first.

Is Cyber Essentials worth it for a small business?

For most small businesses, yes. The five controls it enforces prevent the majority of common cyber attacks, the certificate opens doors with larger clients and public sector buyers, and the included cyber liability insurance is often worth more than the fee itself.

How long is Cyber Essentials valid for?

Twelve months from the date of issue. It must then be renewed, and renewal is assessed against whichever question set is current at the time, so standards do move.

What is the difference between Cyber Essentials and Cyber Essentials Plus?

Cyber Essentials is a verified self assessment. You answer a questionnaire, a board member signs it off, and an assessor marks it. Cyber Essentials Plus adds an independent technical audit, where an assessor scans your network and tests a sample of your devices to confirm the controls genuinely work in practice.

Can I do Cyber Essentials myself?

Yes. The questionnaire is written for business owners rather than IT specialists, and the NCSC publishes free guidance. Most businesses find it far quicker with help, though, particularly if the assessment uncovers problems that need fixing before you can pass.

What happens if I fail Cyber Essentials?

For the basic certification you get feedback on what fell short and an opportunity to correct it and resubmit within a short window. Cyber Essentials Plus is less forgiving, which is why preparation matters far more at that level.

We are Cyber Essentials certified, and we get our clients certified too

We hold Cyber Essentials ourselves, so we have been through exactly what you are about to go through. We know where businesses trip up and we know what the assessors look for.

We support businesses across Chichester, Worthing, Arundel and West Sussex, and we handle cyber security for veterinary practices, solicitors, accountants, architects and construction firms who hold sensitive client data.

If you want to know where you stand before you spend anything, take our free cyber security audit. We will tell you honestly what you would pass on, what you would fail on, and what it would take to fix. No obligation and no hard sell.